Penetration Tester, Vector Command, Social Engineering Specialist in City of Westminster
Penetration Tester, Vector Command, Social Engineering Specialist

Penetration Tester, Vector Command, Social Engineering Specialist in City of Westminster

City of Westminster Full-Time 36000 - 60000 ÂŁ / year (est.) No home office possible
Divvy Cloud Corp.

At a Glance

  • Tasks: Join our team to craft and execute innovative social engineering campaigns.
  • Company: Rapid7, a leader in cybersecurity with a collaborative culture.
  • Benefits: Remote work, competitive salary, and opportunities for professional growth.
  • Why this job: Make a real impact by testing and improving clients' security postures.
  • Qualifications: 5+ years in technical security roles and expertise in social engineering.
  • Other info: Dynamic environment with a focus on teamwork and continuous learning.

The predicted salary is between 36000 - 60000 ÂŁ per year.

Do you enjoy attacking networks? Do you enjoy sifting through large amounts of attack surface, crafting novel attack chains to breach a client’s perimeter, gaining initial access, laterally moving, and demonstrating impact, all while evading security teams and their controls? As a penetration tester on the Global Services team at Rapid7, you will help our clients improve their security posture through your technical skills and knowledge of both offensive and defence strategies.

About the Team

Vector Command is an always-on Red Team operation supporting multiple customers. As part of a specialized team, you will emulate real adversaries by performing large-scale reconnaissance, identifying exposed or high-value assets, and discovering weaknesses that can be leveraged for compromise. After gaining access, the team continues with post-compromise objectives to demonstrate real impact, evade detection, and assess the effectiveness of security controls. This service evaluates far more than vulnerabilities—it tests the customer’s entire security posture and defence-in-depth strategy. In addition to offensive operations, you will support customers through external attack surface analysis, exposure reconnaissance, integration of accounts and tools, preparation of monthly Red Team reports, and prioritization of customer requests. Daily collaboration with Vector Command operators is essential, as is maintaining awareness of new vulnerabilities, shifts in customer attack surfaces, and changes across customer environments.

About the Role

Your primary responsibility is to deliver Rapid7’s Vector Command Continuous Red Teaming service. In this role, you will design social engineering campaigns which function at scale, supporting numerous customers each month, emulating modern adversary TTPs. These campaigns focus on initial access, not click rates, and are often combined with external vulnerabilities or misconfigurations to demonstrate real-world impact. Specifically, your focus will be to:

  • Deploy, configure, and maintain social engineering infrastructure to perform phishing operations at scale.
  • Perform manual and automated reconnaissance at scale to identify targets for social engineering operations each month.
  • Leverage external network vulnerabilities reported by Vector Command team members in targeted real‑world social engineering attacks (incorporate subdomain takeovers, cross‑site scripting, etc. into campaigns).
  • Research the latest techniques in social engineering and implement them in monthly campaigns.
  • Research and test methods to bypass social engineering defenses such as email filters, download restrictions, multi‑factor authentication mechanisms, etc.
  • Be an expert in sending phishing emails which make it to the client’s inbox.
  • Design and execute vishing campaigns.
  • Incorporate payloads provided by the Red Team lead into phishing and vishing operations.
  • Upon successful credential breach or payload execution, evaluate the impact and coordinate with Vector Command team members for post‑compromise breach simulation.
  • Collaborate closely with a team of Red Team operators, participating in daily meetings to establish attack objectives and operational direction.
  • Develop and maintain positive relationships with clients and understand their business and needs.
  • Create additional value for clients through continual insights and consultative advice based on experience with the client, their industry, established standards and leading practices.

The skills and qualities you’ll bring include:

  • 5+ years in an active technical security role
  • Strong knowledge of the following:
  • Advanced Social engineering techniques and tactics
  • Infrastructure management and deployment (domain records, web servers, terraform, ansible, phishing website creation).
  • Modern penetration testing tools and methods
  • Network, wireless and web application security concepts
  • Experience using interpreted languages (Ruby, Python, PHP, etc.)
  • Knowledge of common regulatory structures and obligations and common I.T. governance.
  • Bug Bounty experience, identifying novel vulnerabilities in arbitrary internet‑facing attack surfaces
  • Certifications such as OSCP, OSCE, GXPN, OSEE, CREST
  • Experience with Red & Purple Teams
  • Excellent communication skills both with internal and external stakeholders
  • Collaborative mindset, contributing to knowledge sharing and cross training
  • Demonstrate a commitment to the "end-to-end" testing process, from the initial pre‑engagement planning to providing accountable support during the final remediation phase.
  • Core Value Embodiment: Embody our core values to foster a culture of excellence that drives meaningful impact and collective success. We know that the best ideas and solutions come from multi‑dimensional teams. That’s because these teams reflect a variety of backgrounds and professional experiences. If you are excited about this role and feel your experience can make an impact, please don’t be shy - apply today.

    About Rapid7

    At Rapid7, our vision is to create a secure digital world for our customers, our industry, and our communities. We do this by harnessing our collective expertise and passion to challenge what’s possible and drive extraordinary impact. We’re building a dynamic and collaborative workplace where new ideas are welcome. Protecting 11,000+ customers against bad actors and threats means we’re continuing to push the envelope just like we’ve been doing for the past 20 years. If you’re ready to solve some of the toughest challenges in cybersecurity, we’re ready to help you take command of your career. Join us.

    Penetration Tester, Vector Command, Social Engineering Specialist in City of Westminster employer: Divvy Cloud Corp.

    At Rapid7, we pride ourselves on being an exceptional employer, offering a dynamic and collaborative work environment that fosters innovation and growth. As a Penetration Tester in our Vector Command team, you will have the opportunity to work with cutting-edge technology while developing your skills in social engineering and offensive security strategies. Our commitment to employee development, coupled with a culture that values diverse perspectives, ensures that you will not only contribute to meaningful projects but also advance your career in the ever-evolving field of cybersecurity.
    Divvy Cloud Corp.

    Contact Detail:

    Divvy Cloud Corp. Recruiting Team

    StudySmarter Expert Advice 🤫

    We think this is how you could land Penetration Tester, Vector Command, Social Engineering Specialist in City of Westminster

    ✨Tip Number 1

    Network with industry professionals! Attend cybersecurity meetups, conferences, or online forums. Engaging with others in the field can lead to job opportunities and valuable insights.

    ✨Tip Number 2

    Showcase your skills through practical demonstrations. Create a portfolio of your penetration testing projects or social engineering campaigns. This hands-on evidence can really impress potential employers.

    ✨Tip Number 3

    Prepare for interviews by practising common technical questions and scenarios. Role-play with friends or use mock interview platforms to sharpen your responses and boost your confidence.

    ✨Tip Number 4

    Don’t forget to apply through our website! We’re always on the lookout for talented individuals who can contribute to our mission. Your next big opportunity could be just a click away!

    We think you need these skills to ace Penetration Tester, Vector Command, Social Engineering Specialist in City of Westminster

    Social Engineering Techniques
    Infrastructure Management and Deployment
    Phishing Operations
    Reconnaissance
    Penetration Testing Tools and Methods
    Network Security Concepts
    Web Application Security Concepts
    Experience with Interpreted Languages (Ruby, Python, PHP)
    Bug Bounty Experience
    Red Team and Purple Team Collaboration
    Excellent Communication Skills
    Collaborative Mindset
    Commitment to End-to-End Testing Process
    Knowledge of Regulatory Structures and I.T. Governance

    Some tips for your application 🫡

    Show Off Your Skills: When you're writing your application, make sure to highlight your technical skills and experience in penetration testing. We want to see how you’ve tackled challenges in the past and what tools you’re comfortable using.

    Tailor Your Application: Don’t just send a generic application! Take the time to tailor your CV and cover letter to match the job description. Mention specific experiences that relate to social engineering and network security, as this will show us you’re genuinely interested.

    Be Clear and Concise: Keep your application clear and to the point. We appreciate well-structured applications that are easy to read. Use bullet points where necessary to break down your achievements and skills.

    Apply Through Our Website: Make sure to apply through our website for the best chance of getting noticed. It’s the easiest way for us to keep track of your application and ensure it reaches the right people!

    How to prepare for a job interview at Divvy Cloud Corp.

    ✨Know Your Stuff

    Make sure you brush up on your technical skills, especially around social engineering techniques and penetration testing tools. Be ready to discuss your experience with specific tools and methods you've used in past roles, as well as any novel vulnerabilities you've identified.

    ✨Showcase Your Collaboration Skills

    Since this role involves daily collaboration with the Vector Command team, be prepared to share examples of how you've worked effectively in a team setting. Highlight any experiences where you contributed to knowledge sharing or cross-training, as this will show you're a team player.

    ✨Demonstrate Your Problem-Solving Mindset

    Think about challenges you've faced in previous roles and how you overcame them. Be ready to discuss specific scenarios where you had to design and execute social engineering campaigns or bypass security measures, showcasing your ability to think like an adversary.

    ✨Understand the Client's Needs

    Research Rapid7 and their clients before the interview. Be prepared to discuss how you can create value for clients through insights and consultative advice based on your experience. Showing that you understand their business and needs will set you apart from other candidates.

    Penetration Tester, Vector Command, Social Engineering Specialist in City of Westminster
    Divvy Cloud Corp.
    Location: City of Westminster

    Land your dream job quicker with Premium

    You’re marked as a top applicant with our partner companies
    Individual CV and cover letter feedback including tailoring to specific job roles
    Be among the first applications for new jobs with our AI application
    1:1 support and career advice from our career coaches
    Go Premium

    Money-back if you don't land a job in 6-months

    >